Ajax Security Team
Also reported as Rocket Kitten, Flying Kitten, Operation Woolen-Goldfish, Group 26, SaffronRose and 13 other names. Linked to Iran by three sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2010-0232 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4113 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-7169 KEV
Show all 31 CVEs Show fewer
- CVE-2014-7186
- CVE-2014-7187
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-11774 KEV
- CVE-2018-20250 KEV ransomware
- CVE-2018-8440 KEV ransomware
- CVE-2019-17100
- CVE-2020-10148 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2022-1040 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-26134 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Charming Kitten
-
Magic Hound, APT 35, Cobalt Illusion, Charming Kitten
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Magic Hound, APT 35, Cobalt Illusion, Charming Kitten
-
Rocket Kitten, Newscaster, NewsBeef - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Rocket Kitten, Newscaster, NewsBeef - Threat Group Cards: A Threat Actor Encyclopedia
-
New Core Impact Backdoor Delivered Via VMware Vulnerability
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Core Impact Backdoor Delivered Via VMware Vulnerability
Show all 69 reports Show fewer
-
Experts warn of a spike in APT35 activity and a possible link to Memento ransomware op
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Experts warn of a spike in APT35 activity and a possible link to Memento ransomware op
-
SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group
-
Current Iran-Associated Cyber Threats
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Current Iran-Associated Cyber Threats
-
New steps to protect customers from hacking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New steps to protect customers from hacking
-
Blackgear Cyberespionage Campaign Resurfaces, Abuses Social Media for C&C Communication
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Blackgear Cyberespionage Campaign Resurfaces, Abuses Social Media for C&C Communication
-
Iran’s Cyber Ecosystem- Who Are the Threat Actors-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iran’s Cyber Ecosystem- Who Are the Threat Actors-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iran_Cyber_Final_Full_v2
-
Charming Kitten: Iranian Cyber Espionage Against Human Rights Activists
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Charming Kitten: Iranian Cyber Espionage Against Human Rights Activists
-
Anomali - Iran Country Profile relating to Security.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anomali - Iran Country Profile relating to Security.pdf
-
Magic Hound Campaign Attacks Saudi Targets - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Magic Hound Campaign Attacks Saudi Targets - Palo Alto Networks Blog
-
Iranian hackers behind the Magic Hound campaign linked to Shamoon
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian hackers behind the Magic Hound campaign linked to Shamoon
-
Magic Hound Campaign Attacks Saudi Targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Magic Hound Campaign Attacks Saudi Targets
-
Magic Hound Campaign Attacks Saudi Targets
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Magic Hound Campaign Attacks Saudi Targets
-
iKittens- Iranian Actor Resurfaces with Malware for Mac (MacDownloader)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor iKittens- Iranian Actor Resurfaces with Malware for Mac (MacDownloader)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rocket Kitten
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Rocket Kitten
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Posing as Human Rights Organizations (Iran Threats: Documenting Iranian State Sponsored Hacking)
-
us-16-Guarnieri-Anderson-Iran-And-The-Soft-War-For-Internet-Dominance-paper
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor us-16-Guarnieri-Anderson-Iran-And-The-Soft-War-For-Internet-Dominance-paper
-
Cyber warfare_ Iran opens a new front - FT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber warfare_ Iran opens a new front - FT
-
Rocket Kitten: A Campaign With 9 Lives
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Rocket Kitten: A Campaign With 9 Lives
-
The Spy Kittens Are Back: Rocket Kitten 2
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Spy Kittens Are Back: Rocket Kitten 2
-
London Calling- Two-Factor Authentication Phishing From Iran
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor London Calling- Two-Factor Authentication Phishing From Iran
-
An Iranian Cyber-Attack Campaign Against Targets In The Middle East
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor An Iranian Cyber-Attack Campaign Against Targets In The Middle East
-
Thamar Reservoir – An Iranian cyber-attack campaign against targets in the Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Thamar Reservoir – An Iranian cyber-attack campaign against targets in the Middle East
-
Operation Woolen-Goldfish When Kittens Go Phishing
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Woolen-Goldfish When Kittens Go Phishing
-
Rocket Kitten Showing Its Claws- Operation Woolen-GoldFish and the GHOLE campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rocket Kitten Showing Its Claws- Operation Woolen-GoldFish and the GHOLE campaign
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
Cylance_Operation_Cleaver_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cylance_Operation_Cleaver_Report
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Saffron Rose
-
Sayad (Flying Kitten) Infostealer - malware analysis
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sayad (Flying Kitten) Infostealer - malware analysis
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Molerats, Here for Spring!
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Saffron Rose
-
Cat Scratch Fever- CrowdStrike Tracks Newly Reported Iranian Actor as FLYING KITTEN
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cat Scratch Fever- CrowdStrike Tracks Newly Reported Iranian Actor as FLYING KITTEN
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cat Scratch Fever: CrowdStrike Tracks Newly Reported Iranian Actor as FLYING KITTEN » Adversary Manifesto
Newest first. Details opens the report in Explore.